Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 65 pages
Exam (elaborations)

CompTIA SecurityX (CASP+) CAS 005 Certification Exam Practice Question Bank - Version 2.0 Advanced-Level Practice Questions for Security Architects, Senior Security Engineers, and Enterprise Security Practitioners a well detailed one 2025 / 2

Document preview thumbnail
Preview 4 out of 65 pages

CompTIA SecurityX (CASP+) CAS 005 Certification Exam Practice Question Bank - Version 2.0 Advanced-Level Practice Questions for Security Architects, Senior Security Engineers, and Enterprise Security Practitioners a well detailed one 2025 / 2026 written and graded A+ upgraded

Content preview

1




CompTIA SecurityX (CASP+) CAS-
005 Certification Exam Practice
Question Bank - Version 2.0
Advanced-Level Practice
Questions for Security Architects,
Senior Security Engineers, and
Enterprise Security Practitioners
a well detailed one
written and graded A+
upgraded

, 2




Domain 1: Governance, Risk, and Compliance (GRC) – 20% of Exam



Question 1

A multinational organization is implementing a unified compliance framework to address GDPR,
CCPA, and HIPAA requirements simultaneously. Which GRC approach provides the MOST
efficient cross-regulatory compliance management?

A) Maintain separate compliance programs for each regulation
B) Implement a unified controls framework mapped to multiple regulatory requirements
C) Focus exclusively on the most stringent regulation
D) Outsource compliance management to external consultants

-” detailed answer 100 % correct :-”B

Rationale: A unified controls framework mapped to multiple regulatory requirements enables
efficient compliance management by identifying overlapping controls and avoiding duplicate
efforts. Separate programs (A) create redundancy. Focusing only on the most stringent (C)
leaves gaps. Outsourcing (D) doesn't address internal accountability.



Question 2

A security architect is developing a business continuity plan for a global enterprise. Which
metric indicates the maximum acceptable data loss during a disaster scenario?

A) RTO (Recovery Time Objective)
B) RPO (Recovery Point Objective)
C) MTD (Maximum Tolerable Downtime)
D) SLA (Service Level Agreement)

-” detailed answer 100 % correct :-”B

Rationale: RPO measures the maximum acceptable data loss measured in time—how far back
data can be lost without causing unacceptable impact. RTO (A) measures time to recover. MTD
(C) is the maximum total downtime tolerated. SLA (D) is a service commitment.



Question 3

, 3



A security program manager is creating an enterprise risk register. Which risk treatment strategy
involves transferring risk to a third party?

A) Risk Acceptance
B) Risk Mitigation
C) Risk Avoidance
D) Risk Transfer

-” detailed answer 100 % correct :-”D

Rationale: Risk transfer involves shifting risk to a third party, typically through insurance or
outsourcing. Risk Acceptance (A) acknowledges the risk without action. Risk Mitigation (B)
reduces the risk. Risk Avoidance (C) eliminates the risk by avoiding the activity.



Question 4

An organization is implementing NIST SP 800-53 security controls for a federal information
system. Which control family addresses incident response capabilities?

A) AC (Access Control)
B) AU (Audit and Accountability)
C) IR (Incident Response)
D) CP (Contingency Planning)

-” detailed answer 100 % correct :-”C

Rationale: NIST SP 800-53 control family IR (Incident Response) specifically addresses incident
handling, training, testing, and reporting. AC (A) covers access controls. AU (B) covers audit
trails. CP (D) covers contingency planning.



Question 5

A security architect is implementing a third-party risk management program. Which due
diligence activity provides the MOST comprehensive vendor security assessment?

A) Reviewing vendor marketing materials
B) Analyzing vendor SOC 2 Type II reports and conducting on-site audits
C) Checking vendor's website for security certifications
D) Reviewing vendor's stock price and financial reports

-” detailed answer 100 % correct :-”B

, 4



Rationale: SOC 2 Type II reports provide third-party verification of controls over time, and on-
site audits provide direct observation of security practices. Marketing materials (A) are biased.
Website certifications (C) are superficial. Financial reports (D) are irrelevant to security.



Question 6

An organization is developing a data classification policy. Which data classification level requires
the STRONGEST protection controls?

A) Public
B) Internal Only
C) Confidential
D) Restricted / Highly Confidential

-” detailed answer 100 % correct :-”D

Rationale: Restricted or Highly Confidential data requires the strongest protection controls as its
compromise would cause the most significant damage to the organization. Public (A) requires
minimal controls. Internal Only (B) requires moderate controls. Confidential (C) requires strong
controls but not the strongest.



Question 7

A security manager is conducting a risk assessment. Which risk calculation formula correctly
represents Annualized Loss Expectancy (ALE)?

A) ALE = SLE × ARO
B) ALE = AV × EF
C) ALE = SLE + ARO
D) ALE = AV / EF

-” detailed answer 100 % correct :-”A

Rationale: ALE = SLE (Single Loss Expectancy) × ARO (Annualized Rate of Occurrence). Option B
calculates SLE. Options C and D use incorrect formulas.



Question 8

Document information

Uploaded on
July 25, 2026
Number of pages
65
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$26.89

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2970
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions